Skip to content

Archive v0.6: catalog change detection and identity drift - #21

Merged
WangEn merged 26 commits into
mainfrom
archive/v0.6-catalog-drift
Sep 25, 2026
Merged

WangEn merged 26 commits into
mainfrom
archive/v0.6-catalog-drift

Conversation

@WangEn

@WangEn WangEn commented Sep 25, 2026

Copy link
Copy Markdown
Contributor

Goal

Detect source-backed catalog identity changes without rewriting canonical history.

v0.6 builds on the v0.5 source/identity timeline and derives explicit Before → After transitions from chronological identity facts.

Derived drift model

Migration 0008_catalog_identity_drift.sql adds the read model:

modelapse.catalog_identity_drift_events

It derives two change types:

  • alias_target_changed
    • canonical Model changed
    • provider Snapshot changed
  • execution_binding_changed
    • endpoint changed
    • API model ID changed
    • Snapshot changed

Repeated identical observations remain provenance but do not emit drift.

Execution-binding replacement is recognized only when the predecessor was explicitly closed and ended no later than the successor begins. Parallel routes are not automatically treated as replacement drift.

Historical invariants

v0.6 strengthens catalog history:

  • alias_resolution_events become append-only;
  • new alias observations validate Provider / Model / Snapshot consistency;
  • execution bindings cannot be deleted;
  • execution-binding identity fields are immutable;
  • a current binding may only be closed once;
  • a closed binding cannot be reopened or rewritten.

First-party identity observer

Adds:

PgModelCatalogAdmin.observeFirstPartyIdentity(...)

The observer:

  1. serializes observations per canonical Model with a PostgreSQL advisory transaction lock;
  2. records a fresh Source Record per retrieval;
  3. resolves/creates the observed provider Snapshot;
  4. compares the logical current first-party-direct route across endpoints;
  5. closes/replaces the execution binding only when endpoint / API model / Snapshot changes;
  6. appends a chronological alias observation.

A generic catalog-admin observe-first-party-identity CLI exposes the same primitive for cron/collector workflows without opening a catalog-write HTTP API.

Public Archive

Adds:

GET /v1/archive/changes
  ?modelId=<optional UUID>
  &provider=<optional provider slug>
  &limit=<1-100>

Public drift records contain Archive-safe source summaries only. Raw observation JSON and Source Record metadata remain private.

Model Detail also includes identityDrift.

Web

Adds public /changes:

  • Provider filter
  • Model filter
  • change-type filter
  • explicit Before → After identity states
  • changed-field labels
  • source citation for the later observation

Model Detail embeds relevant drift transitions and links to the global feed.

The UI does not assign severity, infer provider intent, or treat identity drift as evidence of behavioral improvement/regression.

Integration coverage

Catalog integration tests verify:

  • repeated same-state observations create fresh source observations but no drift;
  • Snapshot changes produce alias + execution-binding drift;
  • alias observations cannot be rewritten;
  • binding identity cannot be rewritten.

Persistence integration verifies:

  • Snapshot + endpoint transitions are detected;
  • Model Detail embeds the derived changes;
  • the global Archive change projection returns source-safe summaries;
  • private raw-observation sentinels do not leak.

@WangEn
WangEn merged commit cb6b5e4 into main Sep 25, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant